Back to cactuscompute.com

Privacy Policy

Last updated 16 September 2026

This policy explains what Cactus Compute, Inc. does with personal data when you use the Needle fine-tuning platform. We are a Delaware corporation at 1111B S Governors Ave STE 25802, Dover, DE 19904, United States, our systems run in the United States, and we are the controller for the data described here. Write to founders@cactuscompute.com with any question about it, including a request to exercise your rights.

What we hold

  • Account data: your email address, authentication records, and API keys you create.
  • Customer content: the dataset files you upload, the datasets we generate at your request, and the model exports produced from them.
  • Usage records: runs you submit, their status, timings, sizes, evaluation scores, and request logs needed to operate and secure the service.
  • Billing data: your subscription status and billing period. Card details go directly to Stripe; we never receive them.

Why, and on what basis

  • To provide the service you have asked for, including training, evaluating and delivering your models. Basis: performance of our contract with you.
  • To operate, secure and improve the platform: diagnosing failed runs, investigating abuse, enforcing limits, and keeping backups. Basis: our legitimate interests in running a reliable, safe service.
  • To take payment and meet accounting duties. Basis: contract, and our legal obligations.

We do not use your content to train our own models or any other customer's, we do not sell it, and we do not use it for advertising.

Who can see your uploaded content

You should assume that our staff can access the files you upload and the models you produce. Access is limited to the people who need it to run the platform, and only for these purposes: fixing a failed or stuck run, investigating a security or abuse report, responding to a support request from you, and meeting a legal obligation. Everyone with access is bound by confidentiality, access is logged, and we look at the least data needed for the task. We do not read customer content for any other reason.

Processors we use

  • Supabase: authentication, database and file storage.
  • Vercel: hosting for the website and API.
  • Google Cloud: the machine that schedules runs.
  • RunPod: GPU and CPU machines that execute runs.
  • Nebius: GPU and CPU machines that execute runs.
  • OpenRouter: the model provider used for data generation.
  • Stripe: payments and subscription management.
  • Resend: delivery of authentication email.

These providers act on our instructions under written terms and may not use your data for their own purposes. Business customers who need a data processing agreement should write to us.

How long we keep it

  • Files and model exports: until you delete them. If your subscription ends, they remain for 30 days and may then be deleted; the billing page shows the date.
  • Account and usage records: for as long as you have an account, and for a short period afterwards to resolve disputes.
  • Billing records: for as long as tax and accounting law requires.

Deleting a file removes it from storage. Backups age out on their own schedule.

Your rights

Wherever you live, you may ask us for a copy of your personal data, ask us to correct or delete it, or ask us to stop using it. You can delete files and models yourself in the dashboard at any time. Write to us to exercise any of these rights; we will not treat you differently for asking.

If you are in the European Economic Area, the United Kingdom or Switzerland

The General Data Protection Regulation applies to you. In addition to the rights above you may object to processing we carry out on the basis of legitimate interests, ask us to restrict processing, and receive your data in a portable form. You may complain to your national supervisory authority, which in the United Kingdom is the Information Commissioner's Office.

Your data is transferred to the United States, where we and our providers operate. Those transfers rely on the European Commission's standard contractual clauses and the UK Addendum, which we have in place with each provider listed above, together with the encryption, access control and minimisation measures described in this policy.

If you are in California

You may ask what personal information we have collected about you, where it came from, what we do with it and who we share it with; ask us to delete or correct it; and appeal a refusal. We do not sell personal information, and we do not share it for cross-context behavioural advertising. We will not deny you service or charge you a different price for exercising these rights.

Cookies and security

We set only the cookies needed to keep you signed in. Traffic is encrypted in transit, files live in private storage reached through short-lived signed links, and API keys are stored only as hashes. No system is perfectly secure, but we will tell you and the relevant authority about a breach when the law requires it.

Changes

We will post any update here and change the date above. If a change materially affects you, we will tell you before it takes effect.